¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180929
°ä²¼¹¦·ò 2018-09-29¡¾¹¥»÷ÊÂÎñ¡¿FacebookÔâÁãÈÕ·ì϶¹¥»÷£¬Ô¼5000ÍòÓû§µÄ½Ó¼ûÁîÅÆ±»ÇÔ
9ÔÂ28ÈÕFacebookÈ·ÈÏÆäÔâµ½ºÚ¿Í¹¥»÷£¬¹¥»÷ÕßÀûÓÃÁãÈÕ·ì϶ÇÔÈ¡Á˳¬¹ý5000ÍòÓû§µÄ½Ó¼ûÁîÅÆ¡£¸Ã·ì϶´æÔÚÓÚFacebookµÄView AsÖ°ÄÜÖУ¬¿ÉÔÊÐí¹¥»÷ÕßÇÔÈ¡Óû§µÄ½Ó¼ûÁîÅÆ²¢½Ó¼ûÓû§µÄ¸öÈËÐÅÏ¢£¬¶øÎÞÐèÕË»§ÃÜÂë»òË«³É·ÖÑéÖ¤Âë¡£FacebookÒѲÉÈ¡´ëʩԮÊÖ½ü9000ÍòÓû§³ÁÖÃÁ˽ӼûÁîÅÆ£¬²¢½ûÓÃÁËView AsÖ°ÄÜ¡£ÓÉÓÚµ÷²éÈÔ´¦ÓÚÔçÆÚ½×¶Î£¬FacebookÉÐδȷ¶¨ÊÇ·ñÓÐÈκÎÕË»§±»ÀÄÓûòÐÅÏ¢±»½Ó¼û¡£
https://thehackernews.com/2018/09/facebook-account-hack.html
¡¾¹¥»÷ÊÂÎñ¡¿ÃÀÊ¥µØÑǸç¸ÛÔâÀÕË÷Èí¼þ¹¥»÷£¬²¿ÃÅÒµÎñÊÜÓ°Ïì
ÃÀ¹úÊ¥µØÑǸç¸ÛÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬ÆäITϵͳÊܵ½ÇÖº¦¡£¸Û¿ÚµÄ²¿ÃŹ«¼Ò·þÎñÊܵ½Ó°Ï죬Ô̺¬Í£¿¿Ðí¿É¡¢Ã³Ò×·þÎñºÍ¹«¹²¼Í¼µÈ¡£¸Ã¸Û¿Ú°µÊ¾ÒÑÊÕµ½ÀÕË÷µ¥¾Ý£¬ÒªÇóÒÔ±ÈÌØ±Ò½øÐÐÖ§¸¶£¬µ«²¢Î´Åû¶¾ßÌåµÄ½ð¶î¡£Ä¿Ç°ÕâÒ»ÊÂÎñ»¹ÔÚ½øÒ»²½µÄµ÷²éºÍ´¦ÖÃÖУ¬ÉÐδÅû¶¸ü¶à¾ßÌåÐÅÏ¢£¬Ò²²»Ã÷ÏÔ¸ÃÊÂÎñÓë±¾Ô°ÍÈûÂÞÄǸ۵Ĺ¥»÷ÊÂÎñÊÇ·ñ´æÔÚ¹ØÁª¡£
https://www.bleepingcomputer.com/news/security/port-of-san-diego-affected-by-a-ransomware-attack/
¡¾°²È«·ì϶¡¿Google Project ZeroÅû¶ÐÂLinuxÄں˷ì϶¼°ÆäPoC
Google Project ZeroµÄ°²È«×êÑÐÈËÔ±Jann Horn·¢ÏÖÐÂLinuxÄں˷ì϶£¨CVE-2018-17182£©¡£¸Ã·ì϶ÊÇLinuxÄÚ´æÖÎÀí×ÓϵͳÖеÄuse-after-free·ì϶£¬¿ÉÔÊÐí·ÇÌØÈ¨Óû§ÌáȨÖÁrootȨÏÞ¡£×êÑÐÈËÔ±»¹Åû¶ÁËÓйØPoC¡£LinuxÄں˿ª·¢ÍŶÓÒѾÔÚ×îеİ汾Öн¨¸´Á˸÷ì϶£¬µ«½ØÖÁÖÜÈýDebianºÍUbuntuÖÐÉÐδÔ̺¬¸Ã½¨¸´²¹¶¡¡£
https://thehackernews.com/2018/09/linux-kernel-exploit.html
¡¾°²È«·ì϶¡¿ZDIÅû¶¸»Ê¿µç»úAlpha 5ϵͳÖеĶà¸öÉÐ佨¸´µÄ°²È«·ì϶
ZDIÅû¶ÈÕ±¾µçÆøÉ豸¹«Ë¾¸»Ê¿µç»úµÄAlpha 5ÖÇÄÜËÅ·þϵͳÖеĶà¸ö°²È«·ì϶£¬°æ±¾3.7¼°Ö®Ç°µÄ°æ±¾Êܵ½Ó°Ïì¡£¸Ã²úÆ·ÖØÒªÓÃÓÚÑÇÖÞºÍÅ·ÖÞµÄóÒ×ÉèÊ©ºÍ¹Ø¼üÔì×÷²¿ÃÅ¡£·ì϶Ô̺¬»º³åÇøÒç¶Âí½Å£¨CVE-2018-14794ºÍCVE-2018-14788£©£¬¿Éµ¼ÖÂËÁÒâ´úÂëÖ´Ðм°Ãô¸ÐÐÅϢй¶¡£´Ë±í£¬Æ¾¾ÝICS-CERT£¬»¹Ô̺¬Á½¸ö»º³åÇøÒç¶Âí½Å£¨CVE-2018-14802ºÍCVE-2018-14790£©¡£¸»Ê¿µç»úÐû³ÆÔÚÖÂÁ¦½¨¸´ÕâЩ·ì϶¡£
¡¾¶ñÒâÈí¼þ¡¿×êÑÐÍŶӷ¢ÏÖÖØÒªÕë¶ÔÅ·ÑÇ´ó½ºÍ¶«ÄÏÑǵÄжñÒâÈí¼þNOKKI
Palo Alto NetworksµÄUnit 42ÍŶӰ䲼¹ØÓÚжñÒâÈí¼þNOKKIµÄ·ÖÎö»ã±¨¡£¸Ã¶ñÒâÈí¼þÓë֮ǰµÄ¶ñÒâÈí¼þ¼Ò×åKONNI´æÔÚ´úÂë³ÁµþºÍ»ù´¡ÉèÊ©³Áµþ£¬Òò¶øÆä±³ºóµÄ¹¥»÷Õß¿ÉÄÜÊÇͳһ¸ö¡£NOKKIµÄ¶ñÒâ»î¶¯ÖØÒªÕë¶ÔÅ·ÑÇ´ó½ÒÔ¼°¶«ÄÏÑǵØÓò£¬ÆäÖ¸±êÍùÍùÓµÓÐÕþÖζ¯»ú¡£ÆäC2·þÎñÆ÷λÓÚº«¹ú¾³ÄÚ¡£×ܵÄÀ´Ëµ£¬Æ¾¾ÝC2ºÍ̸µÄ·ÖÆç£¬×êÑÐÈËÔ±ÔÚ2018ËêÊ×µ½2018Äê7ÔÂÆÚ¼ä¹²¹Û²ìµ½Á½²¨¹¥»÷º£³±¡£
https://researchcenter.paloaltonetworks.com/2018/09/unit42-new-konni-malware-attacking-eurasia-southeast-asia/
¡¾¶ñÒâÈí¼þ¡¿×êÑÐÈËÔ±ÔÚGoogle PlayÖз¢ÏÖÒøÐÐľÂíRazdel
ESET×êÑÐÈËÔ±ÔÚGoogle PlayÖз¢ÏÖÒøÐÐľÂíRazdel£¬¸ÃľÂí¼Ù×°³Éµç»°ºÍÓïÒô¼Ôìapp QRecorder£¬ÖØÒªÕë¶ÔÅ·ÖÞÒøÐеÄÓû§¡£RazdelÊÇÒøÐÐľÂíBankBotµÄÒ»¸ö±äÖÖ£¬Æ¾¾Ý°²È«×êÑÐÔ±Lukas StefankoµÄ˵·¨£¬¸ÃľÂíµÄÏÂÔØ´ÎÊý´ï1ÍòÂŴΡ£RazdelÕë¶ÔµÄÒøÐÐÔ̺¬Air Bank¡¢Equa¡¢ING¡¢Bawag¡¢Fio¡¢OberbankºÍBank Austria¡£Æ¾¾Ý½Ý¿Ë¾¯·½µÄÉêÃ÷£¬QRecorder¹²Ï°È¾ÁË5Ãû½Ý¿Ë¹«Ãñ£¬²¢´ÓËûÃǵÄÕË»§ÖÐÇÔÈ¡Á˳¬¹ý7.8ÍòÅ·Ôª¡£
https://securityaffairs.co/wordpress/76637/malware/qrecorder-app-malware.html


¾©¹«Íø°²±¸11010802024551ºÅ